Jérôme Segura

Security Researcher at Malwarebytes focusing on web threats

2024-09-23

#malvertising Obsidian

2024-09-19

@Lee_Holmes @briankrebs for better or worse PowerShell has become somewhat associated with malicious activity (for those in the security space looking at malware).

Remote desktop applications have also inherited a bad reputation as scammers often use them.

But you are absolutely correct, getting the user to do anything at this point is the issue.

2024-09-16

Credit card 'img' skimmer domain:

trendgurupro[.]com

Part of this campaign: malwarebytes.com/blog/news/202

2024-09-11

@Ericlaw is Internet Explorer still being used or is that the default title header?

2024-09-11

Malicious Google Ads for Apple suport

hxxps[://]applescustomerservice24x7care1102[.]vercel[.]app/

hxxps[://]apples24x7-customersupporthelp[.]github[.]io/saf/

2024-09-10

Malicious Google Ad for WinSCP

winscp[.]corysound[.]com
winscpp[.]net
badlink58[.]com/wp-includes/fonts/WinSCP-6.3.4.zip

A Google search for WinSCP; the top ad is maliciousNetwork traffic using mitmproxy
2024-09-09

Malicious Google ad for Microsoft Support

hxxps[://]microsft-customer-helpline[.]vercel[.]app

A malicious Google ad for Microsoft support
2024-09-05
A malicious Google ads leads to a phishing site for Lowe's employee portal.
2024-08-30

Malicious Google Ad for Cisco AnyConnect

cisco[.]com[.]gruaselpiojito[.]com[.]mx

cisco[.]com[.]gruaselpiojito[.]com[.]mx/download/cisco-secure-client-win-5[.]0[.]05040-core-vpn-predeploy-k9[.]exe

NetSupport RAT, C2: sivacycle[.]com

virustotal.com/gui/file/c43272

2024-08-28

@Lee_Holmes Not really, but I just started digging into this more recently so I suspect there are many variations of it.

Come to think of it, it's just a form of spam, looking for any way they can inject data into legitimate/official sources.

2024-08-27

Malicious Google ad for Zoom

pacificfisherman[.]com
zoomi[.]company
zoomi[.]company/Zoom[.]exe

virustotal.com/gui/file/21b075

2024-08-26

SocGholish/FakeUpdates

jswebcloud[.]com
premium[.]davidabostic[.]com

C2: contest[.]printondemandmerchandise[.]com

2024-08-26

@Lee_Holmes thanks, I'm glad it's not just disabling one URL at a time, but an entire account.

Here's the larger campaign I was talking about. Not sure what MSFT can do about it, but it's a real issue: malwarebytes.com/blog/scams/20

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst